upvote
Side channel is academic at best.

Watching memory changing on a complex code base without having said code base is near impossible.

1. Run code 2. Watch memory changes 3. Correlate those to real data

If your code is doing anything complicated that's an intense thing to determine. If you're deep enough for a side channel there's likely a lot easier way of getting in.

reply
Brainfart on my part. I was referring to what @majorchord was worrying about, the unencrypted messages in the client get exfiltrated and get sent to the spooks using steganography on some benign request, edited my comment.

My mental model is that most competent intelligence agencies have a PRISM 3.0 deal with FAANG, including on E2E products or at least have devs on the payroll. I imagine that any backdoor is only used on important targets, so no intel sharing with Cletus the deputy.

reply
Yeah Cletus and Chud aren't getting many secrets but I get the feeling Apple's incentives here are against this.

What financial gain do they get from this?

A: risk billions in stock value and customer purchases for basically a "thanks" from the gov? One whistleblower would also have the real ability of becoming world famous for "exposing" apple.

B: Get publicity actually resisting the gov and not lying, what is the gov gonna do? I imagine it has and does happen but I also imagine there's a crying tim apple being dragged through it painfully.

Unlike google I just don't see the financial positives for them to do it beyond massive arm twisting. For many companies the risk of destroying their entire value to customers is just not worth it.

The only money in it is mass scale data collection for training data and ads, if they aren't doing that any other method is the opposite of valuable it's a massive liability.

reply